FOUNDER OPERATING INTELLIGENCEExecutive Intelligence Scan

Privacy

Privacy Notice — Executive Intelligence Scan

This Privacy Notice explains how personal data is processed through the website and the verified scan, analysis, storage, review and delivery workflow.

Effective 9 August 2026 · Version 1.0

Who operates the service

This website presents the Executive Intelligence Scan and related services operated by Gerry Lingen. Gerry Lingen is the controller for personal data processed in connection with those services.

Contact address: Overtoom 308 2hg, 1054 JD Amsterdam, the Netherlands.

Privacy contact: gerry@liveleadtrigger.ai.

Intended users and minors

The service is intended for entrepreneurs, companies and business leaders in a business context. It is not intended or permitted for minors.

What information is collected

The public website does not provide an account, checkout or payment form. It links visitors to a language-specific Tally intake for the Executive Intelligence Scan.

The scan may collect contact and identity details, including a founder or client name and email address; organisation and role details; business, workflow and operational-challenge information; free-text responses; and submission metadata needed to receive and route the intake. The live intake has been reviewed against these data categories. Free-text fields may still allow users to provide information that was not specifically requested, so users should avoid including unnecessary sensitive personal information.

Why information is used

Relevant information is used to receive and route the scan, understand the organisation and its operational challenges, perform intake analysis, prepare an Executive Intelligence Report, conduct internal review, document the service workflow and deliver the client-facing output after separate human authorisation.

Legal bases

We process personal data only where a valid legal basis applies.

Where an individual personally requests and receives the Executive Intelligence Scan, personal data objectively necessary to provide the requested service may be processed because it is necessary to perform a contract or to take steps requested by that individual before entering into one, in accordance with Article 6(1)(b) of the GDPR.

Where a company or other organisation is the client and personal data relates to a founder, director, employee or other representative, we may process limited business contact and service-related information where necessary for our legitimate interests in providing, administering and documenting the requested B2B service and communicating with the organisation through its representatives, in accordance with Article 6(1)(f) of the GDPR.

We may also rely on legitimate interests for limited security, service-integrity, prevention of accidental duplicate delivery, error-investigation, delivery-evidence and accountability purposes, and where applicable to establish, exercise or defend legal claims. We rely on those interests only where they are not overridden by the individual's rights and interests.

Where processing or retention is required by applicable law, we may process personal data to comply with a legal obligation, in accordance with Article 6(1)(c) of the GDPR.

Consent is not used as the general legal basis for providing the Executive Intelligence Scan. If a separate activity is introduced for which consent is legally required, consent will be requested separately.

Technical journey and service providers

The verified journey uses Tally for the language-specific intake, Cloudflare infrastructure for the public HTTPS submission route, OpenAI's API to assist report synthesis and Google/Gmail for client delivery when that delivery has been authorised. The primary processing and storage workflow runs locally on Gerry's systems.

Third-party service providers process limited information where needed to operate the service. The information made available to each provider depends on its function in the journey; not every provider receives the same information. Their processing is also governed by the relevant service arrangements and account configuration.

Local processing and storage

Relevant scan records, business information and generated working materials may be processed and stored locally on Gerry's Mac mini as part of operating and documenting the service. Local records may include intake data, analyses, reports, correspondence status, manifests, indexes and audit information.

The local environment also retains operational logs and backups. Access controls, backup handling and deletion procedures must remain aligned with the final retention and security policy.

AI-assisted analysis and human review

OpenAI's Responses API assists the analysis and preparation of Executive Intelligence Reports. Relevant organisational, business and free-text intake information may be sent to OpenAI when needed for report quality. The implemented workflow minimises identifiers not needed for that purpose and excludes the client's email address from the model context; a client or founder name may remain when needed for personalised report writing.

OpenAI states that API inputs and outputs are not used to train its models by default, and optional API input and output sharing has not been enabled for our organisation. Responses requests use store=false, so OpenAI does not create normal stored-response application state for those requests. This does not mean zero provider retention: because Zero Data Retention and Modified Abuse Monitoring are not enabled, standard OpenAI abuse-monitoring processing may apply and logs containing customer content may be retained for up to 30 days, unless longer retention is legally required. Automated systems assist with analysis and report preparation. Gerry personally reviews the client-facing output before it is approved for delivery.

Website tracking and cookies

No active non-essential analytics or marketing tracking is currently evidenced on the public website, so no cookie banner is currently used on that basis. This statement describes the current site only; the notice and consent approach must be reassessed if tracking or other non-essential browser technologies are introduced.

International transfers

Tally states that its form data is stored in the European Union. The overall service chain is not guaranteed to remain exclusively within the European Economic Area, and some technical providers may process personal information internationally. Where required, applicable contractual or legal safeguards are used for international transfers. The current OpenAI API project uses Global geography and is not configured as an exclusively European data-residency environment.

Retention

Scan and intake records are retained for up to 24 months after the last meaningful client activity. AI prompts and working synthesis material are retained for up to 90 days after the final approved report. Final reports for founding, free and prospective clients are retained for up to 24 months after the last meaningful client activity; reports for paying clients are retained during the active relationship and for up to 24 months afterwards.

Delivery information and send-audit records are retained for up to 24 months, while the final report follows the applicable report-retention rule above. Operational and error logs are generally retained for up to 90 days. Authentication and integration credentials are kept only while the relevant integration remains active and necessary. Backups follow a rolling lifecycle of up to 90 days. Test artifacts are removed after testing where practicable and no later than 30 days.

These periods do not promise automatic or instantaneous deletion. Information may be kept longer where reasonably necessary to comply with legal obligations, establish, exercise or defend legal claims, or investigate security or integrity matters. Information deleted from active production systems may remain temporarily in secured backups until those backups expire under the normal rolling lifecycle; backups are not used as a hidden archive.

Security and confidentiality

The workflow uses technical and organisational controls intended to reduce unnecessary disclosure and to block external report delivery until explicit human approval. Information is handled under an operational commitment to care and confidentiality, without making an absolute promise that technical processing is risk-free or that no service provider is involved. Security, access, incident handling and provider governance are maintained through internal technical and organisational procedures and are reviewed as the service evolves.

Your rights

Depending on the applicable law and circumstances, individuals may have rights to information, access, correction, deletion, restriction, objection and data portability, and may be able to withdraw consent where consent is used.

Requests may be sent to gerry@liveleadtrigger.ai. Reasonable identity verification may be requested where necessary. These rights are subject to applicable legal conditions and exceptions, so a request does not always result in unconditional deletion or another requested outcome.

Complaints

Individuals may lodge a complaint with the competent data-protection supervisory authority. In the Netherlands, this is the Autoriteit Persoonsgegevens.

Contact

Privacy questions and requests can be directed to gerry@liveleadtrigger.ai.

Changes to this notice

We may update this Privacy Notice when the services, providers, applicable law or processing activities change. Where required, material changes will be communicated through an appropriate channel. The current version and effective date are shown above.